Impact
This vulnerability is a heap‑based buffer overflow in the Windows Kernel that can be triggered by a code path that writes beyond the intended bounds of a heap allocation. When executed by a user with local privileges, it allows the attacker to overwrite kernel memory and gain arbitrary execution at ring 0, thereby elevating their privileges to that of the system. The flaw corresponds to CWE‑122 and CWE‑197 as noted in the description.
Affected Systems
The affected products are Microsoft Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025 including Server Core installations. These builds run on x86, x64, or ARM64 architectures as appropriate.
Risk and Exploitability
The CVSS score of 7.8 indicates high severity, but the EPSS score of less than 1 % and absence from the CISA KEV catalog suggest a low probability of widespread exploitation at this time. However, exploitation requires an attacker to already possess local execution privileges and to trigger the vulnerable kernel path, so the likely attack vector is a locally‑authenticated user executing malicious code. Based on the description, it is inferred that successful exploitation would allow the attacker to run arbitrary code with kernel privilege, effectively bypassing all security boundaries on the affected system.
OpenCVE Enrichment